Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
News File Grabber 4.1.0.1 - Subject Line Stack Buffer Overflow (1)
CVE-2007-1037doswindows19 feb 2007
Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code v
23RIESGO
abrir
Exploit-DBVexDay Proof
Spyce 2.1.3 - '/spyce/examples/formtag.spy' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0980webappsphp19 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Spyce 2.1.3 - 'spyce/examples/getpost.spy?Name' Cross-Site Scripting
CVE-2008-0980webappsphp19 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Spyce 2.1.3 - 'spyce/examples/request.spy?name' Cross-Site Scripting
CVE-2008-0980webappsphp19 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Spyce 2.1.3 - 'docs/examples/handlervalidate.spy?x' Cross-Site Scripting
CVE-2008-0980webappsphp19 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' 'support' Local Buffer Overflow (2)
CVE-2006-6563locallinux19 feb 2007
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iTunes 7.0.2 - XML Parsing Remote Denial of Service
CVE-2007-1008dososx19 feb 2007
Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted
23RIESGO
abrir
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 5.05 - XMD5 Remote Buffer Overflow (Metasploit)
CVE-2006-4847remotewindows19 feb 2007
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arb
60RIESGO
abrir
Exploit-DBVexDay Proof
Spyce 2.1.3 - '/docs/examples/redirect.spy' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0980webappsphp19 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
MailEnable IMAPD Professional 2.35 - Remote Buffer Overflow
CVE-2006-6423remotewindows16 feb 2007
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Pro
50RIESGO
abrir
Exploit-DBVexDay Proof
Meganoide's News 1.1.1 - 'Include.php' Remote File Inclusion
CVE-2007-1024webappsphp16 feb 2007
PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
CedStat 1.31 - 'index.php?hier' Cross-Site Scripting
CVE-2007-1020webappsphp16 feb 2007
Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
Turuncu Portal 1.0 - 'H_Goster.asp' SQL Injection
CVE-2007-1022webappsasp16 feb 2007
SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Ezboo Webstats 3.03 - Administrative Authentication Bypass
CVE-2007-1043webappsphp16 feb 2007
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to
23RIESGO
abrir
Exploit-DBVexDay Proof
MailEnable IMAPD Enterprise 2.32 < 2.34 - Remote Buffer Overflow
CVE-2006-6423remotewindows16 feb 2007
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Pro
50RIESGO
abrir
Exploit-DBVexDay Proof
nabopoll 1.2 - 'survey.inc.php?path' Remote File Inclusion
CVE-2005-2157webappsphp15 feb 2007
PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Aktueldownload Haber scripti - 'id' SQL Injection
CVE-2007-1016webappsasp15 feb 2007
SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
MailEnable Professional/Enterprise 2.35 - Out of Bounds Denial of Service
CVE-2007-0955doswindows14 feb 2007
The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to caus
23RIESGO
abrir
Exploit-DBVexDay Proof
WebTester 5.0.20060927 - 'typeID' SQL Injection
CVE-2007-0970webappsphp14 feb 2007
Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
MailEnable Professional/Enterprise 2.37 - Denial of Service
CVE-2007-0955doswindows14 feb 2007
The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to caus
23RIESGO
abrir
Exploit-DBVexDay Proof
Fullaspsite ASP Hosting Site - 'listmain.asp?cat' SQL Injection
CVE-2007-0951webappsasp13 feb 2007
SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Portable OpenSSH 3.6.1p-PAM/4.1-SuSE - Timing Attack
CVE-2003-0190remotemultiple13 feb 2007
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RIESGO
abrir
Exploit-DBVexDay Proof
Fullaspsite ASP Hosting Site - 'listmain.asp?cat' Cross-Site Scripting
CVE-2007-0950webappsasp13 feb 2007
Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
Lotus Domino R6 Webmail - Remote Password Hash Dumper
CVE-2005-2428remotewindows13 feb 2007
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RIESGO
abrir
Exploit-DBVexDay Proof
TaskFreak! 0.5.5 - 'error.php' Cross-Site Scripting
CVE-2007-0982webappsphp13 feb 2007
Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Xaran CMS 2.0 - 'xarancms_haupt.php' SQL Injection
CVE-2006-3176webappsphp13 feb 2007
SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Portable OpenSSH 3.6.1p-PAM/4.1-SuSE - Timing Attack
CVE-2006-5229remotemultiple13 feb 2007
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RIESGO
abrir
Exploit-DBVexDay Proof
Tagit! Tagit2b 2.1.B Build 2 - '/tagmin/addTagmin.php?configpath' Remote File Inclusion
CVE-2007-0900webappsphp12 feb 2007
Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals i
28RIESGO
abrir
Exploit-DBVexDay Proof
Tagit! Tagit2b 2.1.B Build 2 - '/tagmin/editTag.php?configpath' Remote File Inclusion
CVE-2007-0900webappsphp12 feb 2007
Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals i
28RIESGO
abrir
Exploit-DBVexDay Proof
Tagit! Tagit2b 2.1.B Build 2 - '/CONFIG/errmsg.inc.php?configpath' Remote File Inclusion
CVE-2007-0900webappsphp12 feb 2007
Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals i
28RIESGO
abrir
anteriorpágina 547 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.